{"id":"CLSA-2023-1677784249","summary":"Fix CVE(s): CVE-2022-48303, CVE-2021-20193","details":"\n   * SECURITY UPDATE: memory leak in read_header\n     - debian/patches/CVE-2021-20193.patch: Don't return directly\n       from the loop. Instead set the status and break.  Return the\n       status.\n     - CVE-2021-20193.patch\n   * SECURITY UPDATE: a heap buffer overflow\n     - debian/patches/CVE-2022-48303.patch: Check for the end of\n       field after leading byte (0x80 or 0xff) of base-256 encoded\n       header value.\n     - CVE-2022-48303.patch\n   * improve debian/rules to build the project by root","modified":"2026-06-04T10:04:39.671045020Z","published":"2023-03-02T19:10:49Z","upstream":["CVE-2021-20193","CVE-2022-48303"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04-els/CLSA-2023-1677784249"}],"affected":[{"package":{"name":"tar","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tar?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.28-2.1ubuntu0.2+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2023-1677784249.json"}},{"package":{"name":"tar-scripts","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tar-scripts?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.28-2.1ubuntu0.2+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2023-1677784249.json"}}],"schema_version":"1.7.5"}